依存を抱えた主権の獲得

2026年7月16日、Noetra株式会社とNVIDIAは、国産のマルチモーダル基盤モデル開発に向けた国家規模のAI計算基盤を立ち上げると発表しました。Noetraは、ソニーグループ、ソフトバンク、NEC、ホンダの4社を中核に、IT、製造、素材、建設、モビリティ、金融、通信など国内大手44社が出資する基盤モデル開発企業です。経済産業省の大型事業(FRONTiaプロジェクト)の下、総額一兆円で初年度は3,873億円が投じられ、フィジカルAI向けで世界初を謳う国家規模のAIインフラの整備を進めます。この中核となるNVIDIA Vera Rubin AIファクトリーは、国内の代表的なAI計算基盤ABCI 3.0と比べて理論上のAI性能(FP8)で少なくとも30倍を超え、2027年4月から構築を開始、2028年6月の稼働を予定しています。規模感を示すと、運用よりも構築への配分が大きい初年度投資額だけでも、2025年の国内AIインフラ支出額の半分を上回る規模に相当します(IDC Worldwide Quarterly AI Infrastructure Tracker 2026Q1 Release)。

この基盤で開発されるのは、フィジカルAI向けの基盤モデルです。そのフィジカルAIが現実世界と接するインターフェースの一つが、ロボティクスです。昨今はヒューマノイドが注目されがちですが、ITの観点で本質的なのは、多様なロボティクス技術やエッジをつなぎ、最適化し、そこから得たデータを判断へと束ねることにあります。そこには産業競争力に寄与する大きな機会が広がり、具体化はこの基盤で何を生み出せるかにかかっています。

この発表に対し「世界初・国産・オールジャパン」と讃えるのも、「一社への依存」と切り捨てるのも本質を外しています。本件では、日本はフィジカルAI基盤の開発における計算の主権を外部に預け、計算とアーキテクチャの最先端はNVIDIAが担います。一方、民間44社がNoetraへ薄く資本参加し、現場データと実証フィールドを持ち寄り、日本は現場データとモデルの所有権を持とうとしています。純然たる自立でも従属でもない、依存を抱えた主権の先に、日本の挑戦があります。ただし、技術の利用が一層の依存となる場合も考えられます。与えられた枠組みに乗るだけでなく、どのように関係を構築していけるかも日本に問われていきます。さらに、主権の配分よりも成否に関わる肝心な問いは、この体制で本当に使えるものが作れるかどうかにあります。

肝心なのは「主権」ではなく「実行」

そこで、ここから先は実行にあたって現実を見る必要があります。国産基盤モデルSarashinaの主導者が経営を担い、同様にPLaMoを開発したプリファードネットワークスの経営者が共同研究開発の統括責任者としてモデル開発を率い、同社エンジニアが出向して実働することで経営と技術統括の両輪を担います。日本で基盤モデルをスクラッチで作れる希少な人材が指揮系統の中枢に入ることで、技術的な実行力が裏打ちされます。

一方でリスクもこの体制にあります。この基盤は、44社が自社の現場データを持ち寄って初めて動きます。しかし、各社にとって現場データは機密情報であり差別化要素。これを競合と同じ器に預けるには、どこに保管し、誰がアクセスでき、どう守るかというデータ管理とセキュリティの枠組みが必須となります。さらに、これをクリアしてデータを預けられたとしても、各社が供出の見返りに自社の都合をモデルに求め始めれば、ある社は自社製品への最適化を、別の社は自社ドメインの優先を望み、基盤モデルは「誰にとっても最適でない汎用」へと薄まる可能性があります。多くの声を退けて基盤を一本に保つ規律があるかが問われます。

成否は「どのように仕上げられるか」

この事業を測る指標は、GPUの数でも、国費の額でも、主権の有無でもありません。44社の個別最適の要求を調整し、基盤を一本に保つプロダクトマネジメントの規律を持てるかどうかです。技術的な実行力という必要条件は満たされています。残るは十分条件、つまり出資者の声から開発を守るガバナンスです。ここでは44社という数よりも、この体制の重心が実質どこにあるかが開発の方向を左右します。

開発のロードマップは、2026年度から推論基盤モデル、2028年度にオムニモーダル基盤モデル、2030年度に実世界ネイティブAI、という三段階で構成されています。この事業に規律があるかどうかは、まず2026年度に着手する推論基盤モデルが「何を作らなかったか」に表れます。規律により絞り込めるか、すべてを抱え込み方向を見失うか。また、フィジカルAIの実運用にあたっては、人命に関わる場合など、現実世界での検証に長い時間を要します。この慎重さとAIそのものの速い変化とをどう両立させるのか。時間もまた問われています。

今回の発表により、国内無二のAI計算基盤が2028年6月に稼働します。日進月歩のAIにおいて決して短くはないそれまでの期間で問われるのは、この体制でどのように舵を握り、モデルを作り上げていけるかです。そして、この試みが名に値する価値を生むかどうかの分水嶺は、44社が本当に自社の中核データを差し出すかにあります。中核データの提供範囲が十分でなければ期待された効果は限定的になる可能性があります。

もっとも、優れたモデルができることと国家事業としての成否は別です。これは結局のところ、参加する各社が、自社の現場で活用の道を見出せるかにかかっています。関与に濃淡があるのは自然なことである一方、避けるべきは、自社にとっての位置づけを定められないまま、中途半端に担ぎ続けることです。その時間が大きな機会損失になる恐れがあります。自社での活かし方に明確な答えを出せた企業から、フィジカルAIの競争で確かな位置を占めていくとみています。

著者:加藤慎也 シニアリサーチマネージャー、AI and Automation – IDC Japan

関連する調査やご相談について

より詳細なインサイトや市場動向については、当社アナリストへお気軽にご相談ください。

参考データ:

Shinya Kato - Senior Research Manager, AI and Automation - IDC Japan

Shinya Kato is a Senior Research Manager at IDC Japan and is responsible for the data analysis and forecasting team of Japan enterprise infrastructure market. He analyzes the impact of product technology, service offerings, and marketing strategies on enterprise infrastructure market and provides market forecasts, focusing on the domestic enterprise storage systems market. Through understanding technology adoption trends, he also provides insight into emerging devices such as flash, accelerators, and quantum computing. In addition to researching the HPC and AI infrastructure markets, he is also investigating new consumption models such as Hardware-as-a-Service, to help stimulate the market. Prior to joining IDC, he spent more than 10 years at Silicon Graphics, which was later acquired by HPE, where he held various domestic positions in sales, marketing, and business development. He has covered a wide range of businesses, from infrastructure hardware and container-based data center facilities to digital asset management, industrial virtual reality, and software for media & entertainment. He also served as a product manager for enterprise internet security software and appliances at the emerging vendor. He holds a Bachelor of Economics degree from Rikkyo University.

Ask a vendor if your data is safe and you’ll get a yes. Every vendor says yes. In IDC’s advisory conversations with enterprise security teams, that’s the pattern that comes up again and again: the review process collects reassurance. It rarely collects evidence.

Enterprises that get this right don’t stop at a compliance label. They check for automated evidence and audit trails. They look at model monitoring and explainability. And they weigh a vendor’s actual implementation track record: real deployments, real customers willing to go on record. That’s exactly the review your own IT and security team will run on any AI vendor before signing off, whether that vendor is IDC or anyone else.

The Review That Isn’t a Review

A typical vendor questionnaire asks:

  • Do you encrypt data at rest?

  • Do you have SOC 2?

  • Is there an incident response plan?

These are yes/no questions, and yes/no questions get yes/no answers, regardless of whether the underlying control actually holds up under pressure. A security review that can be passed with a checklist only proves one thing: someone filled out a form correctly.

What “Compliant” Actually Means Depends on Who’s Asking

SOC 2 Type I confirms controls exist on a given day. Type II confirms they held up over a period of months. Both show up as “SOC 2 compliant” on a sales page. Neither tells you whether tenant data can bleed across customer environments, whether prompt injection is screened before it reaches a model, or whether your data trains anything. Compliance frameworks are a floor, not a finding.

Download the IDC Quanta Security Brief before your IT Security asks for it.

Architecture Beats Attestation

The security teams that get this right stop asking whether a vendor is compliant and start asking to see it. Show me the encryption key management setup. Show me where tenant isolation is enforced: application-layer controls that keep one customer’s data from ever touching another’s, not just a policy written down on paper. An architecture diagram is harder to fake than a checkbox. Then ask what happens to an uploaded document in the sixty seconds before it reaches the model. Is it screened for prompt injection, meaning malicious instructions hidden inside the file itself, before the model ever sees it?

Five Questions That Change the Conversation

Five questions is a short list on purpose. Security teams don’t have time to run a hundred-point audit on every AI vendor pitching them this quarter.

  1. Where, specifically, is tenant isolation enforced?

  2. What happens to a file between upload and model ingestion?

  3. Is customer data used to train any model, yours or a third party’s?

  4. Who verifies your security rating, and how often?

  5. What’s your actual pen-test cadence, confirmed against the audit log rather than the sales deck?

Want to see IDC Quanta in action? Book a Demo now.

Where Quanta Stands on Those Five Questions

Your own IT and security team will ask us these same five questions before Quanta clears procurement, so we might as well answer them here. And yes, we’re aware of the obvious catch: IDC also owns Quanta, so treat this section exactly like we just told you to treat every vendor’s answers. Verify it. Every spec below is published at trust.idc.com and open for a security team to check.

  1. Tenant isolation is enforced at the application layer. Token-derived identity and SQL scoping keep one customer’s data invisible to every other Quanta user.

  2. Every file uploaded to Quanta passes malware scanning and prompt-injection detection before it ever reaches the model. That’s the same sixty-second window this piece just asked every vendor about.

  3. Customer data trains nothing. Not Quanta’s models, not a third party’s. That’s a permanent commitment, built into the platform rather than a setting anyone could quietly change.

  4. Who verifies the rating? BitSight does, continuously. Quanta scored 800 out of 900 as of July 2026. SOC 2 Type I is compliant today. SOC 2 Type II and ISO 27001:2022 are both actively in progress.

  5. The pen-test cadence is confirmed against the audit log: annual third-party testing plus continuous vulnerability scanning, backed by a 24-vendor, 11-domain zero-trust stack with a monitoring team watching around the clock.

The Path Forward

None of this requires a bigger budget or a longer questionnaire. It requires asking for evidence. Vendors with real architecture behind their claims will show you exactly where each control lives, Quanta included. Pointing back to the checklist is what’s left when there’s nothing else to show. to show.

If you want to run this exact review against Quanta, the specs, certs, and policies are self-serve at trust.idc.com.

Ryan Smith - Content Marketing Director - IDC

Ryan Smith is the Director of Content Marketing at IDC, where he leads brand-level content and social media strategy, aligning research insights with compelling storytelling to engage technology decision-makers. With a background in both IT and marketing, Ryan brings a unique blend of technical understanding and creative strategy to his work. He’s also a seasoned storyteller, speaker, and podcast host who believes the right message, told the right way, can drive both trust and transformation.

2026年7月16日,2026世界人工智能大会暨人工智能全球治理高级别会议开幕前夕,来自29个国家的代表在上海签署《关于成立世界人工智能合作组织的协定》,成为该组织的创始成员国。协定明确,世界人工智能合作组织是独立的政府间国际组织,总部设在上海。

7月17日,大会发布了《2026世界人工智能大会暨人工智能全球治理高级别会议主席声明》《人工智能合作发展行动计划》《国际人工智能伦理治理行动计划》

距离2025年WAIC发布《人工智能全球治理行动计划》并倡议成立世界人工智能合作组织,仅短短一年时间,人工智能全球治理便已落地到组织建设、能力合作、标准协调和运行机制等具体层面。

Agent治理决定企业能够开放多少业务权限

Agent治理已经进入企业风险和投资决策。IDC在2025年10月发布的全球预测中提到,到2030年,多达20%的G1000组织可能因AI Agent控制与治理不足引发高影响力业务事故或中断,面临诉讼、巨额罚款和CIO被解职IDC最新全球调研数据也显示,全球企业计划中的AI投资平均有16.7%用于AI及Agent安全与治理,投入比例已经接近AI技术栈中的其他主要部分(Future Enterprise Resiliency and Spending Survey, Wave 10)。

这些治理要求并非是对Agent的限制,而是真正决定Agent是否能够深入的业务流程的前提。

  • 身份与授权不清晰,企业就难以将核心系统开放给Agent;
  • 缺少链路观测和行为日志,企业就无法还原Agent的判断与执行过程;
  • 缺少流程暂停、任务回退和人工接管机制,企业也难以在Agent出现异常时控制其连锁影响。

只有当Agent的身份、权限、行动过程和异常处置都处于可验证、可追溯、可控的范围内,企业才可能放心地让它进入核心业务,读取真实数据并执行具体操作。

全球AI经济需要共同的信任基础

Agent开展跨组织、跨平台协作时,企业内部的治理机制还要与外部规则连接。身份标识和协作互认帮助不同主体识别彼此,接口协议负责建立连接,语义与流程兼容支持任务理解和协同,行为验证与追溯则为信任和责任提供依据。

一个Agent要接入另一套系统,需要确认其身份、授权来源、能力范围和风险等级。系统还要判断它能否读取某类数据、调用某个工具、修改某项状态,以及哪些操作必须等待人工确认。

不同的身份体系、协议和评测标准会增加Agent经济的交易成本。如果每个平台都使用独立的身份体系、协议和评测方法,跨平台协作就需要反复进行技术适配、安全验证和风险评估。共同的Agent身份标识、安全基线和互操作协议可以减少重复工作,降低不同组织之间Agent交互的成本。

全球Agent经济要实现规模化运行,各方需要围绕Agent身份认证、安全基线和互操作规则形成基本共识,并建立相对统一的标准。在此基础上,Agent才能跨越平台、组织和市场执行任务,不同组织也才愿意开放数据、工具和业务能力,让Agent之间的协作形成可验证、可复制、可持续的生产与交易关系。

全球AI经济需要共同的信任基础

全球治理提出的身份互认、行为追溯和风险分级,最终会体现在企业Agent的系统建设和任务执行中。

  • 身份互认进入企业,会形成Agent账号、授权主体和凭证管理机制;
  • 行为可追溯进入业务流程,会形成任务日志、工具调用记录和责任归属;
  • 风险分类分级则决定Agent可以访问哪些数据、执行哪些操作,以及哪些节点需要人工确认。

以一份企业报价为例,Agent需要读取客户信息、产品配置、库存情况和折扣规则,还要识别销售人员的权限、判断报价是否超过审批额度,并把结果写回业务系统。如果客户信息涉及敏感数据,系统需要限制读取范围;如果折扣超过阈值,任务需要转入人工审批;如果写回失败,Agent还要保存当前状态,避免重复提交或生成两份相互冲突的报价。

这样的治理需求也会逐渐改变企业评估Agent的方法,未来企业除了关注Agent完成任务的成本和准确率,还需要重点关注Agent能否遵守权限约束,能否在任务执行失败时可控回退,以及能否在关键节点及时转交人工审查。


WAIC 2026全球治理议程关注的一个核心问题,是如何管理能够代表人和组织执行任务的AI。AI 及Agent 应用能进入多深的业务流程,取决于治理能力能否跟上。企业内部的身份、权限和行为记录,平台之间的互操作与验证,国家之间的规则协调与能力建设,共同构成AI经济的信任基础。规则越清楚,企业越有可能向Agent开放真实数据、业务工具和核心流程;共同基线和互认机制越完善,Agent跨组织、跨平台和跨市场协作的成本也会越低。治理既约束风险,也为AI能力的大规模应用提供通行条件。

给企业和技术厂商的行动倡议

1. 为Agent建立独立身份与账号

Agent身份需要明确授权主体、数据范围、工具权限和人工确认节点。不同风险等级的任务需要配置不同的执行边界。低风险操作可以自动完成,涉及敏感数据、资金、合同和生产状态的操作,应保留审批、暂停和人工接管机制。

2. 让Agent的执行过程可观测、可回退、可追溯

企业需要记录Agent的任务输入、数据读取、工具调用、业务状态修改和人工介入,形成完整的行动链路。

出现异常时,系统应能暂停任务、保存当前状态、回退相关操作,并定位异常发生的环节及其影响范围。

3. 用可验证的评测说明Agent的能力边界

技术厂商需要说明Agent在不同权限、异常和跨系统环境中的表现。除了任务成功率,还应提供越权拦截、失败恢复、人工介入逻辑和风险控制机制等评测结果,便于企业判断Agent适合进入哪些业务流程,以及可以获得多大的权限范围。

4. 为Agent跨系统、跨组织协作做好准备

Agent连接外部平台时,应能够提供可验证的身份、授权来源、能力范围和任务目的。企业也需要根据Agent的身份、授权来源和风险等级,明确可以向其开放哪些数据和工具、授权持续多长时间,以及哪些操作需要再次确认。

技术厂商则需要支持身份凭证传递、权限委托与撤销、标准化能力描述和互操作协议,让不同平台上的Agent能够在清楚的授权边界内协作。

进一步交流

如果您希望了解人工智能相关的研究或开展进一步交流,欢迎点击这里与我们联系!

Zhenya Sun - Research Manager - IDC

Zhenya Sun is a research manager for the IDC team focused on exploring the application of technology and industrial development of AI and AI agents. He is also responsible for providing clients with consulting services on technologies, products, and markets related to large language models (LLMs) and AI agents, as well as delivering speeches at industry conferences and internal seminars. Before joining IDC, Zhenya served as a project management officer (PMO), responsible for internal and external strategic consulting, AI application research and advisory services, AI project framework standardization, management system construction, and technical training on AI applications. Prior to that, he also led initiatives in product development process optimization and user market analysis. Zhenya holds a Master's Degree in Engineering Management with a specialization in Information Systems Engineering from the University of the Chinese Academy of Sciences.